Administration

Table Of Contents
6 Right-click the imported certificate and add a friendly name such as vdm.ec (for Enrollment
Client certificate).
VMware recommends you use a friendly name that identifies the Horizon 7 cluster, but you can
use any name that helps you easily identify the client certificate.
What to do next
Configure the SAML authenticator used for delegating authentication to VMware Identity
Manager. See Configure SAML Authentication to Work with True SSO.
Configure SAML Authentication to Work with True SSO
With the True SSO feature introduced in Horizon 7, users can log in to VMware Identity Manager
2.6 and later releases using smart card, RADIUS, or RSA SecurID authentication, and they will no
longer be prompted for Active Directory credentials, even when they launch a remote desktop or
application for the first time.
With earlier releases, SSO (single sign-on) worked by prompting users for their Active Directory
credentials the first time they launched a remote desktop or published application if they had not
previously authenticated with their Active Directory credentials. The credentials were then cached
so that subsequent launches would not require users to re-enter their credentials. With True SSO,
short-term certificates are created and used instead of AD credentials.
Although the process for configuring SAML authentication for VMware Identity Manager has not
changed, one additional step has been added for True SSO. You must configure VMware Identity
Manager so that True SSO is enabled.
Note If your deployment includes more than one Connection Server instance, you must associate
the SAML authenticator with each instance.
Prerequisites
n Verify that single sign-on is enabled as a global setting. In Horizon Administrator, select
Configuration > Global Settings, and verify that Single sign-on (SSO) is set to Enabled.
n Verify that VMware Identity Manager is installed and configured. See the VMware
Identity Manager documentation, available at https://docs.vmware.com/en/VMware-Identity-
Manager/index.html
n Verify that the root certificate for the signing CA for the SAML server certificate is installed
on the connection server host. VMware does not recommend that you configure SAML
authenticators to use self-signed certificates. See the topic "Import a Root Certificate and
Intermediate Certificates into a Windows Certificate Store," in the chapter "Configuring SSL
Certificates for Horizon 7 Servers," in the
Horizon 7 Installation
document.
n Make a note of the FQDN of the VMware Identity Manager server instance.
Procedure
1 In Horizon Administrator, select Configuration > Servers.
Horizon 7 Administration
VMware, Inc. 107